CVE-2023-43797

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 30, 2023
Updated: Nov 7, 2023
CWE ID 79

Summary

CVE-2023-43797 is a cross-site scripting (XSS) vulnerability affecting versions prior to 2.6.11 and 2.7.0-beta.3 of the open-source virtual classroom software, BigBlueButton. The Guest Lobby feature was found to be susceptible to XSS attacks due to the insertion of unsanitized messages into an element using unsafe innerHTML. This issue could potentially allow attackers to inject malicious scripts into unsuspecting users' browsers while they wait in the lobby to enter a meeting. A patch has been released in versions 2.6.11 and 2.7.0-beta.3, which include text sanitization for lobby messages to mitigate this vulnerability. Unfortunately, there are currently no known workarounds for affected users until they upgrade to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • BigBlueButton
  • BigBlueButton BigBlueButton

Affected Vendors

  • BigBlueButton Inc.